{"id":11154,"date":"2026-03-06T10:04:08","date_gmt":"2026-03-06T10:04:08","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/06\/google-confirms-90-zero-day-vulnerabilities-actively-exploited-in-2025\/"},"modified":"2026-03-06T10:04:08","modified_gmt":"2026-03-06T10:04:08","slug":"google-confirms-90-zero-day-vulnerabilities-actively-exploited-in-2025","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/06\/google-confirms-90-zero-day-vulnerabilities-actively-exploited-in-2025\/","title":{"rendered":"Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025"},"content":{"rendered":"<p>    Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>The Google Threat Intelligence Group (GTIG) released its annual analysis, confirming that <a href=\"https:\/\/cybersecuritynews.com\/chrome-zero-day-2025\/\" target=\"_blank\" rel=\"noreferrer noopener\">90 zero-day vulnerabilities<\/a> were actively exploited in the wild throughout 2025.<\/p>\n<p>While this marks a slight decrease from the record 100 zero-days in 2023, it represents a noticeable increase from 2024\u2019s total of 78.<\/p>\n<p>According to Google\u2019s researchers, attackers are shifting their focus away from browsers and heavily targeting enterprise infrastructure, mobile operating systems, and <a href=\"https:\/\/cybersecuritynews.com\/apt-hackers-target-edge-devices\/\" target=\"_blank\" rel=\"noreferrer noopener\">edge devices to achieve widespread network access<\/a>.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-expanding-attack-surfaces\"><strong>Expanding Attack Surfaces<\/strong><\/h2>\n<p>In a significant landscape shift, <a href=\"https:\/\/cybersecuritynews.com\/ios-zero-day-exploit-chain-leveraged\/\" target=\"_blank\" rel=\"noreferrer noopener\">Commercial Surveillance Vendors (CSVs)<\/a> overtook traditional state-sponsored espionage groups as the primary drivers of zero-day exploitation.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg9n39UGVFFMTIp-d4zwH2K3lwj0vs5wqjQ0Y0XAoTCxeNXguZp4vEL62yemTEbR9Li9S764wzTfnAtQCUEgNAhQqb4F9aX14SXVUz4vqSz88CcqI3naD7-KTO7IjmCPrq7d0Ynok1WxkKUUg8zpXFO2QkyCMmHTIrToGTgVhg4whyxV9PYa3VI5qqMsb8\/s1600\/Screenshot%25202026-03-06%2520103906%2520%25281%2529.webp?ssl=1\" alt=\"Attributed 2025 zero-day exploitation (Source: Google)\"><figcaption class=\"wp-element-caption\"><em>Attributed 2025 zero-day exploitation\u00a0(Source: Google)<\/em><\/figcaption><\/figure>\n<p>These vendors continue to develop complex exploit chains to <a href=\"https:\/\/cybersecuritynews.com\/popular-zero-day-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">bypass modern security boundaries on mobile devices<\/a>.<\/p>\n<p>Consequently, mobile zero-day discoveries rebounded to 15 in 2025, forcing attackers to chain multiple bugs together to achieve deep system access. Meanwhile, enterprise technologies accounted for 48% of all exploited zero-days.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgRLj0ibhqfWvr9nJy9osUsNtgG3JicFlM_aBM3iDC5XFzMsU-BdvXjh4bBiM8Ic8C3ogLlCJx6hnAlEP5jZw5u9_U04SBPRG7fgXc5uVbpDCSFEUZFCFtMauKvsvNSOValQTw1E75fY9-qiYll1OSPwjF7Rry3pcBNq86IN1Z5OX_luAXzrWJKiVlYJsw\/s1600\/Screenshot%25202026-03-06%2520103821%2520%25281%2529.webp?ssl=1\" alt=\" 2025 zero-days in end-user vs enterprise products (Source: Google)\"><figcaption class=\"wp-element-caption\"><em>\u00a02025 zero-days in end-user vs enterprise products\u00a0(Source: Google)<\/em><\/figcaption><\/figure>\n<p>Networking and security appliances remain highly vulnerable due to their privileged network positions and lack of built-in endpoint detection capabilities.<\/p>\n<p>State-sponsored groups, specifically <a href=\"https:\/\/cybersecuritynews.com\/unc3886-actors-know-for-exploiting-0-days\/\" target=\"_blank\" rel=\"noreferrer noopener\">PRC-nexus operators like UNC3886<\/a> and UNC5221, consistently targeted these edge devices for long-term espionage.<\/p>\n<p>Threat actors are also evolving their ultimate objectives.<a href=\"https:\/\/cybersecuritynews.com\/cisa-releases-indicators-of-compromise-tied-to-brickstorm-malware\/\" target=\"_blank\" rel=\"noreferrer noopener\"> A 2025 malware campaign known as BRICKSTORM<\/a> highlighted a new paradigm where state-sponsored attackers targeted technology companies to steal proprietary source code.<\/p>\n<p>This stolen intellectual property accelerates the discovery of future zero-day vulnerabilities, creating a dangerous cycle of exploitation.<\/p>\n<p>Furthermore, financially motivated actors matched previous records by exploiting nine zero-days, proving that advanced exploits are no longer strictly limited to espionage.<\/p>\n<p>As attackers increasingly <a href=\"https:\/\/cybersecuritynews.com\/privacy-first-ai-workflows\/\" target=\"_blank\" rel=\"noreferrer noopener\">use AI to accelerate vulnerability<\/a> discovery and exploit development, organizations must adopt layered defense mechanisms.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjx3is0O7E8tBJmeMMEjPSlDKbecdU3MZuj_TaoylwJe_YCrjtylDd4oQRGITTPriDBP3_5-cf4XeWzLDjphI3g5koBzd42GYusCDj4nD3ehuumjUs0bZhS7GYAr0MCla8t8eZj1dMAbaciXb14dnLCkZBDFW4bTTNpXAH0PKBbWC0ftjuaMV4SpLWpDoM\/s1600\/Screenshot%25202026-03-06%2520103835%2520%25281%2529.webp?ssl=1\" alt=\"2025 zero-day exploitation by vendor (Source: Google)\"><figcaption class=\"wp-element-caption\"><em>2025 zero-day exploitation by vendor\u00a0(Source: Google)<\/em><\/figcaption><\/figure>\n<p><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/2025-zero-day-review\" id=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/2025-zero-day-review\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GTIG emphasizes that security teams should prepare<\/a> for eventual compromise by implementing strict network segmentation and maintaining a real-time asset inventory.<\/p>\n<p>A core defense strategy involves tracking a <a href=\"https:\/\/cybersecuritynews.com\/software-composition-analysis-explained\/\" target=\"_blank\" rel=\"noreferrer noopener\">Software Bill of Materials (SBoM)<\/a> to identify vulnerable components when new zero-days emerge rapidly.<\/p>\n<p>The 2025 threat landscape demonstrates that as vendors secure basic software flaws, threat actors rapidly pivot to more complex, highly privileged enterprise environments.<\/p>\n<p>Security teams must prioritize edge device monitoring, strict access controls, and rapid remediation to defend against these escalating campaigns.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/google-confirms-90-zero-day-vulnerabilities-exploit-in-2025\/\">Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/google-confirms-90-zero-day-vulnerabilities-exploit-in-2025\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google Confirms 90 Zero-Day Vulnerabilities Actively Exploited in 2025 The Google Threat Intelligence Group (GTIG) released its annual analysis, confirming that 90 zero-day vulnerabilities were actively exploited in the wild throughout 2025. While this marks a slight decrease from the record 100 zero-days in 2023, it represents a noticeable increase from 2024\u2019s total of 78. [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,2169,163,416],"tags":[130],"class_list":["post-11154","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-exploit","category-google","category-vulnerabilities","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11154"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11154"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11154\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11154"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11154"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11154"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}